Legal
Privacy policy
Who we are
Garmin Community MCP ("we", "us") operates a hosted Model Context Protocol server that lets AI assistants you choose access your Garmin Connect data at your instruction. Contact: privacy@garmincommunitymcp.com. We are not affiliated with Garmin Ltd., OpenAI or Anthropic.
What we collect
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account, sign-in links, service emails | Contract | Until account deletion |
| Encrypted Garmin authentication token | Fetching your Garmin data when your AI asks | Consent (you connect Garmin) and contract | Until you disconnect or delete your account |
| Garmin display name, profile id, time zone | Addressing Garmin API requests; date handling | Contract | Until disconnect |
| Connector token hash | Authenticating your AI client | Contract | Until rotated or deleted |
| Tool-call counts and tool names, write audit entries | Rate limits, support, showing you what the AI changed | Legitimate interest | 90 days |
| Payment details | Billing | Contract | Held by Stripe; we store the Stripe customer id and plan |
| Support emails | Helping you | Legitimate interest | 2 years |
| Error logs (no tool arguments or results) | Reliability | Legitimate interest | 30 days |
Health data
Your Garmin health and activity data is special-category data under GDPR and sensitive information under other laws. We process it only to pass it from Garmin to the AI client you connected, at that client's request, which you initiated. We do not store it, analyse it, sell it, or use it to train anything. It is not written to disk or logs. The AI provider you use (OpenAI, Anthropic or another) receives it under their own privacy policy.
Sub-processors
- Cloudflare, Inc.: hosting, database, cache, cookieless analytics.
- Stripe, Inc.: payments and tax.
- Resend, Inc.: transactional email.
We don't use advertising trackers or third-party cookies. The only cookie is a session cookie on the dashboard.
Your rights
Access, correction, deletion, portability, restriction and objection, where applicable under GDPR, UK GDPR, the Australian Privacy Act 1988, CCPA and similar laws. Delete your account from the dashboard to erase everything within 24 hours, or email privacy@garmincommunitymcp.com. EU/UK users may lodge a complaint with their supervisory authority.
International transfers
Our infrastructure runs on Cloudflare's global network; data may be processed outside your country under standard contractual clauses or equivalent safeguards.
Children
The service is for people 16 and over.
Changes
We'll email account holders about material changes at least 14 days before they take effect.